> Markdown version of [/jobs/ext/2051252-grc-manager-cyber-security](https://www.wearedevelopers.com/jobs/ext/2051252-grc-manager-cyber-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Manager - Cyber Security - **Company:** Gleeson Recruitment Ltd - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management System - **Published:** August 14, 2026 - **Apply:** https://www.careerboard.com/pt/en/find-jobs-in-United-Kingdom/-2CE275977C79C0B5C3/ ## About the Role The key requirement is someone who has personally helped take an organisation through ISO 27001 certification and understands what successful implementation looks like in practice. You'll ideally bring: * Strong practical experience across information security Governance, Risk & Compliance. * Experience developing or significantly maturing a GRC function or ISMS. * End-to-end ownership of ISO 27001 controls, evidence, audits and remediation. * Experience managing security risks and driving actions through to completion. * Exposure to third-party/supplier assurance and customer security requirements. * Knowledge of NIS2 would be particularly valuable. * Excellent stakeholder management and communication skills. You'll need the confidence to challenge and influence people across the organisation, translating complex security risks into clear business language for audiences ranging from technical teams through to senior executives. We're open on industry background. More important is your ability to operate autonomously, adapt best practice to a lean environment and take genuine ownership rather than being one part of a large GRC function. ## Description We are looking for an experienced GRC Manager to join a growing Information Security function within a PE-backed international organisation undergoing significant growth and transformation. Reporting directly to the Director of Information Security, you'll take ownership of Governance, Risk and Compliance activities across the business, with an immediate focus on supporting the organisation through ISO 27001 certification. This is an opportunity to have genuine ownership. We're not looking for someone who has simply contributed to GRC within a large team; we need someone who understands how to take frameworks, controls and best practice and implement them effectively within a lean, fast-moving organisation. The Role You'll take ownership across: * Driving the organisation's ISO 27001 certification journey and ongoing ISMS maturity. * Developing and maintaining security policies, standards and governance frameworks. * Managing information security risks, risk registers, treatment plans and remediation. * Coordinating audit evidence, control assessments and audit readiness. * Supporting compliance with NIS2, NCSC CAF, GDPR and Cyber Essentials. * Managing third-party security assessments, supplier assurance and customer security questionnaires. * Producing meaningful security KPIs, KRIs and executive reporting. * Working across IT, OT, Legal, Procurement, Operations and Commercial teams to drive security improvements. * Supporting security awareness, business continuity and post-incident improvement activities. * Continuously improving and automating GRC processes as the organisation grows. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job)